CVE-2018-7334: High severity Wireshark Wireshark vulnerability
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umtsmac.c by rejecting a certain reserved value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wiresharkto a version that resolves this vulnerability.Fixed in 2.6.20-0+deb10u4Fixed in 2.6.20-0+deb10u7Fixed in 3.4.10-0+deb11u1Fixed in 4.0.6-1~deb12u1Fixed in 4.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7334?
CVE-2018-7334 is considered a medium severity vulnerability as it can cause a denial of service due to application crashes.
How do I fix CVE-2018-7334?
To fix CVE-2018-7334, update Wireshark to version 2.6.20 or later, 3.4.10 or later, or any version starting from 4.0.6.
What versions of Wireshark are affected by CVE-2018-7334?
CVE-2018-7334 affects Wireshark versions from 2.4.0 to 2.4.4 and from 2.2.0 to 2.2.12.
Which platforms are impacted by CVE-2018-7334?
CVE-2018-7334 impacts Wireshark on Debian Linux versions 7.0, 8.0, and 9.0.
Can CVE-2018-7334 be exploited remotely?
CVE-2018-7334 does not allow for remote exploitation; it requires processing specially crafted packets.